German employee data protection is governed by the Bundesdatenschutzgesetz (BDSG — Federal Data Protection Act), which supplements and specifies the EU General Data Protection Regulation (GDPR) in the German context. The BDSG adds specific provisions for employee data, including a list of permissible processing purposes, restrictions on employee consent, and rules on video monitoring and profiling. The Federal Commissioner for Data Protection and Freedom of Information (BfDI) is the national supervisory authority. Employee data processing must comply with both the GDPR and the BDSG, and the interaction between the two creates traps for employers who treat the GDPR as the sole framework.
This guide covers the BDSG provisions specific to employment, the lawful bases for processing employee data, employee consent in the employment context, and the practical compliance obligations.
Key takeaways
- German employee data protection is governed by both the GDPR (EU Regulation 2016/679) and the BDSG (Bundesdatenschutzgesetz) — you must comply with both.
- Section 26 BDSG provides a specific legal basis for processing employee data in the employment context — including for purposes of the employment relationship, exercising rights, and fulfilling legal obligations.
- Employee consent in the employment context is generally not considered freely given due to the power imbalance — the BDSG and GDPR both recognise this problem.
- The BDSG requires a Datenschutz-Folgenabschätzung (Data Protection Impact Assessment) for processing that is likely to result in a high risk to the rights and freedoms of employees.
- Video monitoring of employees is subject to strict requirements under Section 4 BDSG — proportionality, transparency, and no monitoring of areas where employees have a legitimate expectation of privacy.
The BDSG and the GDPR — the interplay
The GDPR sets the baseline across all EU member states. The BDSG supplements it with Germany-specific provisions, particularly in the employment context. The key BDSG provisions for employee data are:
| BDSG provision | What it covers |
|---|---|
| Section 26 | Processing of employee data — the primary legal basis for employment-related data processing |
| Section 26(1) | Processing necessary for the employment relationship |
| Section 26(2) | Processing for exercising rights or fulfilling obligations under collective agreements |
| Section 26(3) | Consent of the employee — and the limits on its validity |
| Section 4 | Video monitoring of employees |
| Section 40 | Obligation to inform employees about data processing |
Where the BDSG provides more specific rules, those rules take precedence over the GDPR for German employers.
Lawful bases for processing employee data
Section 26(1) BDSG — the employment basis
Section 26(1) BDSG provides that personal data of employees may be processed where it is necessary for the purposes of the employment relationship — including for the decision to enter into an employment contract, its performance or termination, or the exercise or fulfilment of rights and obligations arising from the employment relationship.
This is the German equivalent of the GDPR’s “contractual necessity” basis (Article 6(1)(b) GDPR), but it is specifically tailored to the employment context. The processing must be necessary — the employer cannot process data simply because it is convenient.
Section 26(2) BDSG — collective agreements
Processing is also permitted where it is necessary for the exercise of rights or the fulfilment of obligations arising from a law or a collective agreement — including works agreements (Betriebsvereinbarungen). This basis is relevant for processing related to works council functions, collective bargaining, and sector-specific regulatory requirements.
Section 26(3) BDSG — consent
Where processing is based on consent, the employee’s consent is subject to the general rules of Article 7 GDPR and the additional restriction in Section 26(3): consent is not considered freely given if it is connected with the employment relationship. The employee must be able to refuse without consequences — which is rarely possible in practice.
Employee consent — the problem
The power imbalance between employer and employee means that consent under Article 7(4) GDPR is often not freely given. The GDPR expressly states that consent is not freely given where there is a clear imbalance between the data subject and the controller.
In practice:
- Consent for processing health data, salary data, or disciplinary records is almost never freely given.
- Consent can be withdrawn at any time — Article 7(3) GDPR — and the employer must stop processing and delete the data if there is no other legal basis.
- Relying on consent as the primary basis for employee data processing is a compliance risk.
The better approach is to rely on Section 26(1) BDSG (employment necessity) or legitimate interests (Article 6(1)(f) GDPR), and to use consent only where it is genuinely free — for example, where the employee opts into a newsletter or a benefit that is entirely voluntary.
Special categories of employee data
Special categories of data (health, trade union membership, religious beliefs, etc.) are subject to additional restrictions under both Article 9 GDPR and Section 26(3) BDSG. The employer needs both a lawful basis under Article 6/Section 26 and a condition under Article 9.
The most relevant Article 9 conditions for German employers:
| Condition | When it applies |
|---|---|
| Necessary for employment obligations (Art. 9(2)(b)) | Health data for occupational health assessments, sick pay, workplace safety |
| Explicit consent (Art. 9(2)(a)) | Where the employee has given explicit consent — but the same power-imbalance concerns apply |
| Trade union membership (Art. 9(2)(d)) | Processing necessary for the purposes of the employment relationship — e.g., verifying union status for works council elections |
Video monitoring
Section 4 BDSG permits video monitoring of employees only where:
- There is a legitimate interest that justifies the monitoring.
- The monitoring is proportionate — the least intrusive means of achieving the legitimate aim.
- Employees are informed of the monitoring in advance (transparency).
- Areas where employees have a legitimate expectation of privacy (break rooms, toilets) are not monitored.
The employer must document the proportionality assessment. The works council (Betriebsrat) must be consulted if the monitoring affects the working environment — and in many cases, a works agreement (Betriebsvereinbarung) is required.
The works council and data protection
Where a works council exists, the employer cannot introduce or change monitoring systems without the works council’s consent — Section 87(1) No. 6 Betriebsverfassungsgesetz. The works council has a co-determination right over the introduction and use of technical devices designed to monitor employee behaviour or performance.
This means:
- The employer cannot install CCTV, introduce email monitoring, or deploy workforce management software without the works council’s agreement.
- The works council can demand a works agreement (Betriebsvereinbarung) that sets out the rules for data processing.
- The works council has the right to inspect the data processing and audit compliance.
Common pitfalls
1. Relying on consent as the primary basis
Consent is rarely valid in the employment context. The BDSG and GDPR both recognise that consent given in the shadow of the employment relationship is not freely given.
2. Ignoring the works council
Introducing data processing systems without the works council’s consent is a breach of the Betriebsverfassungsgesetz. The works council can demand the system be switched off.
3. Video monitoring without proportionality assessment
Recording employees without documenting the proportionality assessment and informing employees is a breach of both the BDSG and the GDPR.
4. Not providing the required information
Section 40 BDSG requires employers to inform employees about data processing — particularly where it is not carried out directly from the employee. The information must be specific and accessible.
Putting it into practice
Five steps to build BDSG compliance into your HR processes:
- Map your data flows — know what employee data you process, on what basis, and where it is stored.
- Document your lawful basis — for each processing activity, record whether you rely on Section 26(1), legitimate interests, or another basis.
- Consult the works council — before introducing any new data processing system or changing an existing one.
- Inform employees — provide a clear, accessible privacy notice that covers all data processing activities.
- Conduct a DPIA — where processing is likely to result in a high risk to employee rights and freedoms.
A leave management system that processes employee data in compliance with both the GDPR and the BDSG — with proper lawful bases, transparency, and data minimisation — reduces the compliance burden for German employers.
Sources
- Bundesdatenschutzgesetz (BDSG) (primary source)
- EU General Data Protection Regulation (GDPR) (primary source)
- Betriebsverfassungsgesetz (BetrVG) (works council co-determination)
- Federal Commissioner for Data Protection (BfDI) (supervisory authority)
This article is general information, not legal advice. German data protection law is complex and interacts with works council rights — consult a German data protection specialist for specific situations.